We never store password data in plain text. instead they are stored hashed (with at least 4096 rounds of bcrypt, including both a salt and a server-side pepper secret). Passwords sent to the server are encrypted using SSL.
Previous Status: PENDING
Updated Status: APPROVED
Title: Information is provided about security practices
Analysis: Generated through the annotate view
Status: PENDING